← KEV catalog
CISA known exploited vulnerability

CVE-2021-25487

Samsung Mobile Devices Out-of-Bounds Read Vulnerability

SOURCE FACT

Samsung · Mobile Devices

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

Required action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CISA notes

https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10; https://nvd.nist.gov/vuln/detail/CVE-2021-25487

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?